PT-2021-3819 · Gnu+1 · Glibc+1

Published

2021-08-09

·

Updated

2025-05-30

·

CVE-2021-38604

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions glibc versions through 2.34
Description The issue is related to the mishandling of certain NOTIFY REMOVED data in the sysdeps/unix/sysv/linux/mq notify.c component of the GNU C Library (glibc), leading to a NULL pointer dereference. This can be exploited by a remote attacker to cause a denial of service. The vulnerability was introduced as a side effect of a previous fix and can be triggered through the POSIX message queues API by sending a specially crafted message.
Recommendations For glibc versions through 2.34, consider disabling the mq notify() function or restricting access to the POSIX message queues API as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3034
ALT-PU-2022-2917
AZL-6442
BDU:2021-04132
CVE-2021-38604
MGASA-2021-0404
OESA-2021-1328

Affected Products

Alt Linux
Glibc